Unauthorized FileIO Client Settings Exposure in Apache Polaris
CVE-2026-97395

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-97395?

Apache Polaris enables authenticated users to manage Iceberg table properties, including critical FileIO client settings such as s3.endpoint. In versions prior to 1.8.0, these settings can be exploited during server-side Iceberg operations—like commits and purges—leading to potential misuse of the configured storage endpoint. If the catalog storage configuration fails to override the specified endpoint, Polaris may inadvertently direct storage traffic to an endpoint designated by the table writer, potentially compromising sensitive request authentication materials. This vulnerability poses significant risks when untrusted table writers have the authority to adjust server-side storage endpoints.

Affected Version(s)

Apache Polaris 0 < 1.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vignesh a <imavignesh27@gmail.com>
.